Privacy Policy
Last updated: June 2025
This Privacy Policy explains how Bluehappenworks Casino Hotel collects, uses, discloses, and protects your personal data when you visit our website at www.bluehappenworks.com, make a reservation, use our services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the Australian Privacy Act 1988, and all other applicable data protection legislation.
Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read and understood this policy. If you do not agree with the practices described herein, please discontinue use of our website and services.
1. Data Controller
The entity responsible for processing your personal data (the "Data Controller") is:
| Legal Entity Name | Bluehappenworks Casino Hotel |
|---|---|
| Trading Name | Bluehappenworks Casino Hotel |
| Registration Country | Australia |
| Registration Number | HRB 123456 B |
| VAT Number | AU 123456789 |
| Registered Address | 81 Talavera Rd, North Ryde NSW 2113, Australia |
| Website | www.bluehappenworks.com |
| Privacy Contact Email | privacy@bluehappenworks.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection legislation. You may contact our DPO directly regarding any questions or concerns about how we handle your personal data:
| Title | The Data Protection Officer |
|---|---|
| Organisation | Bluehappenworks Casino Hotel |
| Address | 81 Talavera Rd, North Ryde NSW 2113, Australia |
| privacy@bluehappenworks.com |
2. Personal Data We Collect
We collect personal data that you provide to us directly, data that is generated automatically when you use our website or services, and data that we receive from third parties. The categories of personal data we may collect include, but are not limited to, the following:
2.1 Identity and Contact Data
- Full name (first name, last name)
- Date of birth and age verification information
- Gender
- Nationality and country of residence
- Government-issued identification document details (e.g., passport number, driver's licence number) where required by law
- Postal address (home and billing address)
- Email address
- Telephone number(s)
- Profile photograph (where voluntarily provided)
2.2 Reservation and Stay Data
- Booking reference numbers and confirmation details
- Check-in and check-out dates
- Room type and preferences
- Number of guests and guest details
- Special requests and accessibility requirements
- Loyalty programme membership details
- History of previous stays and interactions with our establishment
2.3 Financial and Payment Data
- Credit card or debit card details (processed securely via PCI-DSS compliant payment processors; we do not store full card numbers)
- Bank account information (where applicable for refunds or transfers)
- Transaction history and records
- Invoicing and billing records
2.4 Casino and Gaming Data
- Casino membership and player club information
- Gaming activity records (types of games played, session duration, amounts wagered and won)
- Self-exclusion programme participation and responsible gambling records
- Age and identity verification records as required by the Casino Control Act 1992 (NSW) (Australia) and any other applicable gaming regulations
- Anti-money laundering (AML) and Know Your Customer (KYC) verification information
2.5 Website and Technical Data
- IP address
- Browser type and version
- Operating system and device type
- Pages visited and time spent on each page
- Referring website URL
- Date and time of access
- Cookie identifiers and session data (see our Cookie Policy for further details)
- Clickstream data and interaction data
2.6 Marketing and Communication Data
- Marketing preferences and opt-in/opt-out records
- Communication history (including emails, letters, and records of telephone calls where calls are recorded)
- Survey responses and feedback submissions
- Competition and promotional entry details
2.7 Special Categories of Personal Data
In limited circumstances, we may collect special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health data: Accessibility and dietary requirements, allergy information, or medical conditions that you voluntarily disclose to enable us to accommodate your needs during your stay.
- Biometric data: Where required for access control or security purposes and where permitted by law.
We will only process special categories of personal data where we have your explicit consent, where processing is necessary to protect your vital interests, or where we are otherwise permitted to do so under applicable law. You are never obligated to provide special category data to us; however, failure to do so may limit our ability to fulfil specific service requests.
2.8 Data Collected from Third Parties
We may also receive personal data about you from the following third-party sources:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia)
- Corporate travel management companies making bookings on your behalf
- Credit reference and fraud prevention agencies
- AML and KYC screening service providers
- Social media platforms (where you engage with our social media presence or use social login features)
- Analytics and advertising partners
3. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we only process your personal data where we have a valid legal basis for doing so. The legal bases we rely upon are described below:
3.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where processing is necessary to enter into or perform a contract with you. This includes:
- Processing your hotel reservation, check-in, and check-out
- Managing your stay, including room service, dining, and facility bookings
- Processing payments for services rendered
- Managing your casino membership and gaming activity in accordance with your agreement with us
- Responding to your pre- and post-stay enquiries that relate to your booking
3.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where we are required to do so by law. This includes:
- Age verification to comply with gambling and liquor licensing regulations
- Anti-money laundering (AML) obligations and Know Your Customer (KYC) verification under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (Australia)
- Tax, accounting, and financial record-keeping obligations
- Compliance with court orders, law enforcement requests, and regulatory investigations
- Fulfilment of obligations under the Casino Control Act 1992 (NSW) (Australia) and Casino Control Act 1990 (Australia)
- Compliance with the Australian Privacy Act 1988
3.3 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process your personal data where it is necessary to protect the vital interests of you or another person, for example, in a medical emergency involving a guest on our premises.
3.4 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms. These legitimate interests include:
- Ensuring the security of our premises, staff, and guests through CCTV surveillance and physical access control
- Fraud detection and prevention
- Improving and optimising our website, services, and customer experience
- Conducting internal analytics, business intelligence, and reporting
- Sending personalised service communications and relevant offers to existing customers (where you have not opted out)
- Managing and defending legal claims
- Network and information security
- Conducting guest satisfaction surveys
Where we rely on legitimate interests, you have the right to object to our processing. Please see Section 8 (Your Rights) for further information.
3.5 Consent (Article 6(1)(a) GDPR)
Where no other legal basis applies, or where required by law, we will seek your consent before processing your personal data. We rely on consent for the following activities:
- Sending direct marketing communications to new contacts or via electronic means (email, SMS) where you have not previously engaged with us as a customer
- Placing non-essential cookies and similar tracking technologies on your device (see our Cookie Policy)
- Processing special categories of personal data (e.g., health data for accessibility requirements) where no other legal basis applies
- Sharing your data with third-party partners for joint marketing purposes
Where we rely on your consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw your consent, please contact us at privacy@bluehappenworks.com or use the unsubscribe mechanism provided in our marketing communications.
3.6 Public Task (Article 6(1)(e) GDPR)
Where applicable, we may process personal data in connection with the performance of a task carried out in the public interest or in the exercise of official authority, for example, in the context of responsible gambling obligations and the public interest in preventing problem gambling.
4. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
4.1 Hotel and Accommodation Services
- Processing, managing, and confirming your reservations and bookings
- Facilitating your check-in and check-out processes
- Providing in-stay services including room service, concierge, housekeeping, and dining
- Accommodating special requests, dietary needs, and accessibility requirements
- Managing your loyalty programme membership and associated benefits
- Processing payments and issuing invoices and receipts
- Managing cancellations, amendments, and refunds
4.2 Casino and Gaming Operations
- Verifying your identity and age as required by gambling regulations
- Registering and managing your casino membership
- Recording and reporting gaming transactions as required by law
- Conducting AML and KYC checks
- Administering responsible gambling measures, including self-exclusion programmes
- Detecting and preventing fraudulent or suspicious gaming activity
- Providing player rewards and loyalty benefits
4.3 Customer Communications and Support
- Responding to your enquiries, complaints, and requests
- Sending booking confirmations, pre-arrival information, and post-stay follow-up communications
- Providing customer support and resolving disputes
- Notifying you of changes to our services, policies, or terms and conditions
4.4 Marketing and Personalisation
- Sending you promotional offers, newsletters, and information about our hotel, casino, dining, and events (subject to your marketing preferences)
- Personalising communications and offers based on your stay history, preferences, and interests
- Conducting competitions, prize draws, and promotional activities
- Displaying targeted advertising on our website and third-party platforms (subject to your cookie and advertising preferences)
4.5 Security and Safety
- Operating CCTV systems throughout our premises to ensure the safety and security of guests, staff, and property
- Managing physical access to restricted areas of our property
- Preventing and investigating theft, fraud, and other criminal activity
- Ensuring compliance with health and safety regulations
- Responding to emergencies on our premises
4.6 Legal and Regulatory Compliance
- Fulfilling our obligations under applicable laws and regulations
- Responding to requests from regulatory bodies, law enforcement agencies, and courts
- Establishing, exercising, or defending legal claims
- Maintaining records required by tax and accounting laws
4.7 Business Analytics and Improvement
- Analysing website traffic, usage patterns, and user behaviour to improve our website and online services
- Conducting market research and guest satisfaction surveys
- Generating internal business reports and performance analytics
- Developing new products, services, and offerings
5. Sharing Your Personal Data
We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients where necessary and in accordance with applicable law:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instruction. These include:
- IT and technology providers: Hosting services, cloud computing providers, property management system providers, and software vendors
- Payment processors: Secure payment gateway providers and card processing companies (PCI-DSS compliant)
- Booking and reservation platforms: Online travel agencies and channel management systems
- Marketing and communications: Email marketing platforms, CRM system providers, and advertising technology partners
- Customer support: Call centre and customer support technology providers
- Analytics providers: Website analytics and business intelligence platforms
- Security providers: CCTV monitoring services and physical security companies
- AML and KYC verification providers: Identity verification and screening services
All third-party processors are required to implement appropriate technical and organisational security measures and are only permitted to process your personal data in accordance with our instructions and applicable data protection law.
5.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to the following authorities where required or permitted by law:
- The Australian Federal Police
- Liquor & Gaming NSW
- AUSTRAC and other financial crime regulators
- The Australian Taxation Office (ATO)
- Other regulatory bodies, tax authorities, and government agencies as required
- Courts and judicial bodies in connection with legal proceedings
5.3 Business Partners
Where you have provided your consent or where we have another lawful basis to do so, we may share your personal data with selected business partners for the following purposes:
- Joint marketing and promotional activities
- Linked loyalty programme partners
- Event management and entertainment partners providing services on our premises
5.4 Corporate Transactions
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such change in data controller and ensure appropriate protections are in place.
5.5 International Data Transfers
As a business operating within Australia, the majority of your personal data is stored and processed within Australia or the European Economic Area (EEA). However, some of our service providers may operate in or transfer data to countries outside of Australia and the EEA. Where personal data is transferred to a country that does not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions recognised by the relevant data protection authority
- Binding Corporate Rules (BCRs) where applicable
- Other legally approved transfer mechanisms
You may request further information about international data transfers and the safeguards in place by contacting us at privacy@bluehappenworks.com.
6. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The criteria we use to determine appropriate retention periods include the nature and sensitivity of the data, the purposes for which it is processed, applicable statutory limitation periods, and regulatory requirements.
The following retention periods apply as a general guideline:
| Category of Data | Retention Period | Reason |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of stay | Legal and tax obligations; limitation periods for civil claims |
| Financial and payment records | 7 years from the date of transaction | Tax and accounting obligations under Australia law |
| Casino membership and gaming records | 7 years from the date of last activity or account closure | Gambling regulatory requirements and AML obligations |
| AML/KYC verification records | 5 years from the end of the business relationship | Anti-Money Laundering and Countering Financing of Terrorism Act 2009 |
| CCTV footage | 31 days (unless required for investigation or legal proceedings) | Security purposes; proportionality principle |
| Marketing and communication preferences | Until you withdraw consent or opt out, plus 1 year | Compliance with marketing opt-out records |
| Website analytics and technical data | Up to 26 months | Business analytics and improvement |
| Customer complaints and correspondence | 3 years from resolution | Legal claims and dispute resolution |
| Responsible gambling and self-exclusion records | Duration of exclusion plus 5 years | Regulatory compliance and duty of care obligations |
Upon expiry of the applicable retention period, your personal data will be securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data is anonymised, it may be retained indefinitely for statistical and analytical purposes.
7. Your Rights Under Data Protection Law
Subject to applicable data protection legislation, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to certain exceptions and limitations under applicable law.
7.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly referred to as a Subject Access Request (SAR). We will respond to your request within one month of receipt, which may be extended by a further two months in complex or numerous cases.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you have withdrawn your consent and no other legal basis applies, or where the data has been unlawfully processed. This right does not apply where we are required to retain the data to comply with a legal obligation or to establish, exercise, or defend legal claims.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, where you contest the accuracy of the data, where processing is unlawful and you oppose erasure, or where you have objected to processing and we are verifying whether our legitimate interests override your rights.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another controller where technically feasible.
7.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- Legitimate interests: Where we process your data on the basis of our legitimate interests, you may object on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
- Direct marketing: You have an unconditional right to object to processing of your personal data for direct marketing purposes at any time. Upon receipt of such an objection, we will cease processing your data for that purpose immediately.
7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we engage in automated decision-making that has significant effects, we will inform you accordingly and provide you with the opportunity to request human review, to express your point of view, and to contest the decision.
7.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
7.9 How to Exercise Your Rights
To exercise any of your rights, please submit a written request to us using the contact details provided in Section 8 below. We may need to verify your identity before processing your request. We will respond to your request within one calendar month. There is no charge for exercising your rights, unless requests are manifestly unfounded or excessive, in which case we reserve the right to charge a reasonable fee or refuse to act on the request.
7.10 Right to Lodge a Complaint
If you are not satisfied with how we handle your personal data or with our response to a rights request, you have the right to lodge a complaint with the relevant supervisory authority. In Australia, the relevant authority is:
| Authority | Office of the Australian Information Commissioner (OAIC) |
|---|---|
| Website | www.oaic.gov.au |
| Phone | 1300 363 992 |
| Address | GPO Box 5218, Sydney NSW 2001, Australia |
If you are located within the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so that we may address your concerns directly before escalating to a supervisory authority.
9. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, loss, or destruction. These measures include, but are not limited to:
- Encryption of data in transit using TLS (Transport Layer Security) and encryption of sensitive data at rest
- Secure and access-controlled data storage systems
- Role-based access controls limiting access to personal data to authorised personnel only
- Regular security assessments, penetration testing, and vulnerability management
- Staff training on data protection and information security
- PCI-DSS compliant payment processing for all card transactions
- Incident response and data breach notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify you without undue delay where required by law.
Please note that no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security. We encourage you to use strong passwords, keep your account credentials confidential, and notify us immediately if you suspect any unauthorised access to your account.
10. Children's Privacy
Our casino services are strictly available to persons aged 18 years and over in compliance with Australian gambling legislation. Our website is not directed at children under the age of 18, and we do not knowingly collect personal data from children under this age in relation to our casino services.
Hotel accommodation services may be used by families with children; however, personal data relating to minors will only be processed to the extent necessary to fulfil the hotel booking and will be handled with the utmost care. Where parental or guardian consent is required for the processing of a minor's data, we will seek such consent.
If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at privacy@bluehappenworks.com so that we may take appropriate steps to delete such data.
11. Third-Party Links and Services
Our website may contain links to third-party websites, applications, and services that are not operated or controlled by us. This Privacy Policy does not apply to those third-party websites and services. We are not responsible for the privacy practices of third parties and encourage you to review the privacy policies of any third-party websites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. The date at the top of this policy indicates when it was last revised. Material changes will be communicated to you by posting a prominent notice on our website or, where appropriate, by direct notification to you by email.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website and services following any update constitutes your acknowledgement of the revised policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we process your personal data, please do not hesitate to contact us using the following details:
| Data Controller | Bluehappenworks Casino Hotel |
|---|---|
| Contact Person | The Data Protection Officer |
| Postal Address | 81 Talavera Rd, North Ryde NSW 2113, Australia |
| Email Address | privacy@bluehappenworks.com |
| Website | www.bluehappenworks.com |
We are committed to addressing your queries and concerns promptly and in a transparent manner. If you are not satisfied with our response, you retain the right to lodge a complaint with the Office of the Australian Information Commissioner or any other competent supervisory authority, as described in Section 7.10 of this policy.